Skip to content
Last updated

Power BI integration

Power BI is Microsoft's business intelligence platform for semantic models, reports, and dashboards.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through Microsoft's hosted Power BI MCP server, so your AI agents can read semantic model and report metadata, generate DAX from natural-language questions, and run DAX queries, authenticated through a Microsoft Entra ID app you register.
  • In-house — Agen.co wraps the Power BI REST API directly through its own integration layer, giving agents access to datasets, reports, dashboards, workspaces, and dataflows.

Pick Official to let agents answer questions from your semantic models. Fall back to In-house to list and manage datasets, reports, dashboards, workspaces, and dataflows.


Connect via the official MCP server

Prerequisites

  • Microsoft Fabric active in your tenant, with at least one Fabric or Power BI licence assigned there. Without it, the Fabric API's service principal is disabled in the tenant, and Microsoft stops the connection before any sign-in screen with AADSTS500014: The service principal for resource 'https://api.fabric.microsoft.com' is disabled. The error message says a subscription within the tenant has lapsed, which points to the same cause.
  • The Power BI tenant setting Users can use the Power BI Model Context Protocol server endpoint (preview) enabled, or a Fabric administrator who can enable it. Until the setting applies, which can take up to 15 minutes after it's enabled, the server answers both initialize and tools/list with JSON-RPC error -32003 FeatureNotAvailable, even after a successful sign-in.
  • Permission to register applications in the Microsoft Entra ID tenant that hosts your Power BI environment. If your tenant requires admin consent for delegated permissions, you also need an administrator who can grant it.
  • Build permission on at least one Power BI semantic model for each user who signs in. Every tool runs as the signed-in user.

Agen.co connects to Microsoft's hosted Power BI Consumption MCP server (https://api.fabric.microsoft.com/v1/mcp/powerbi). It's in preview, and Microsoft now recommends Fabric IQ for new consumption scenarios. The server reads and queries semantic models. It can't create or change them.

Enable the Power BI MCP endpoint

  1. Sign in to the Power BI Admin portal as a Fabric administrator and open Tenant settings.
  2. Find Users can use the Power BI Model Context Protocol server endpoint (preview), enable it for your organization or for the security groups that will use the connector, and click Apply. Tenant setting changes can take up to 15 minutes to apply.

Copy the callback URLs from Agen.co

Microsoft Entra ID has no dynamic client registration, so you register an app yourself. It needs the callback URLs that Agen.co generates, so start in Agen.co.

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. Search for Power BI and select it. In the Add Power BI panel, keep Official selected.
  3. Copy both read-only URLs at the bottom of the panel:
    • Callback URL: completes the initial OAuth handshake between Agen.co and your Entra app.
    • Gateway callback URL: used by the Agen.co MCP gateway for per-user authorization at runtime.

Leave this panel open. You return to it after registering the Entra app.

Register a Microsoft Entra ID app

  1. In a new browser tab, sign in to the Microsoft Entra admin center and open App registrations → New registration.
  2. Enter a name (for example, Agen.co Power BI MCP). Under Supported account types, select Accounts in this organizational directory only (Single tenant), and click Register.
  3. On the app's Overview page, copy the Application (client) ID.
  4. Open Manage → Authentication → Add a platform → Web. Add both URLs you copied from Agen.co as redirect URIs, and click Configure.
  5. Open Manage → API permissions → Add a permission. Select Power BI Service, choose Delegated permissions, add the three permissions below, and click Add permissions.
PermissionWhy the connector needs it
Dataset.Read.AllRead semantic model schemas and run DAX queries against them
MLModel.Execute.AllRequired by Microsoft for the Consumption MCP server
Workspace.Read.AllRead the workspaces that hold the semantic models and reports
  1. If your tenant requires admin consent, click Grant admin consent for [YOUR TENANT] and confirm. If it doesn't, each user consents the first time they sign in.
  2. Open Manage → Certificates & secrets → New client secret, add a description and an expiry, and click Add. Copy the secret Value right away. It's shown only once.

Add all three permissions before you connect

Agen.co requests the resource-wide https://api.fabric.microsoft.com/.default scope, which the MCP server publishes. With .default, Microsoft Entra ID issues a token with only the Power BI Service permissions configured on this app, so a permission you leave out is never requested at sign-in and is simply absent from the token.

Connect Power BI in Agen.co

  1. Return to the Add Power BI panel you left open and fill in the fields:
FieldRequiredDescription
Instance SlugYesNamespaces this instance. It prefixes each imported tool as slug__tool, so a second instance of the same connector needs its own slug. Use lowercase kebab-case, for example powerbi. You can change it later from the connector's settings.
Client IDYesThe Application (client) ID of the Entra app you registered.
Client SecretYesThe client secret Value from the Entra app.
  1. Click Connect. You're redirected to Microsoft to sign in and approve access.
  2. Back in Agen.co, the panel shows Select the tools to import from Power BI. with a toggle for each tool, all on by default. Turn off any tool you don't want, then click Add. The connector is created and its tools imported only when you click Add, even if the Microsoft sign-in page reported success.

Once connected, Power BI appears under My connectors with Microsoft's four Consumption server tools:

ToolTool nameWhat it does
Get Semantic Model SchemaGetSemanticModelSchemaReads a semantic model's tables, columns, measures, relationships, hierarchies, and any AI instructions the model author configured
Get Report MetadataGetReportMetadataReads a report's pages, visuals, field bindings, and filters, which shows how the report uses its semantic model
Generate QueryGenerateQueryTurns a natural-language question into a DAX query using Copilot in Power BI. It requires a Copilot license for the user or organization and consumes Copilot capacity.
Execute QueryExecuteQueryRuns a DAX query against a semantic model and returns the results

Agen.co imports each tool with the instance slug as a prefix, for example powerbi__ExecuteQuery. Use these exact names when you write the policy for this connector.

Every tool takes a semantic model ID or a report ID as input, and none of them lists workspaces, models, or reports. Give your agents the IDs they need. A semantic model's ID is the last segment of its URL in the Power BI service: https://app.powerbi.com/groups/{workspaceId}/datasets/{semanticModelId}. Queries run as the signed-in user, so row-level security on the model applies.

Enabling the Power BI connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the Power BI REST API

Integrating Microsoft Power BI with Frontegg allows your application to read and manage datasets, reports, dashboards, workspaces, dataflows, and apps in a Power BI tenant through the Power BI REST API — all via Frontegg's integration layer using Microsoft Entra ID OAuth 2.0.


Prerequisites

  • A Microsoft account with access to the Azure portal
  • A Microsoft Entra ID (Azure AD) tenant where you can register applications
  • A Power BI account (Power BI Pro, Premium Per User, or Power BI Premium capacity is required for some endpoints such as dataflows and report export)

Register an application in Azure

Step 1: Open App registrations

Sign in to the Azure portal and open App registrations (you can search for it in the top search bar or open it directly from Microsoft Entra ID → App registrations). Click New registration at the top of the page.

App registrations page in Azure portal

Step 2: Register a new application

Fill in the registration form:

  1. Enter a name for your application (for example, Frontegg Power BI Integration).
  2. Under Supported account types, select Accounts in any organizational directory (Any Microsoft Entra ID tenant — Multitenant) for multi-tenant apps, or Accounts in this organizational directory only for a single-tenant app.
  3. Under Redirect URI, choose Web as the platform and enter:
    https://YOUR_MCP_GATEWAY_URL/integration-callback
  4. Click Register.

New application registration form with name, multitenant account type, Web platform, and redirect URI filled in

Step 3: Copy the Application (client) ID and Directory (tenant) ID

After registration, you are taken to the application Overview page. Copy both the Application (client) ID and the Directory (tenant) ID — you will need them when configuring the Frontegg portal.

Application overview page with Application (client) ID and Directory (tenant) ID highlighted

Create a client secret

Step 4: Open Certificates & secrets

In the left sidebar, under Manage, click Certificates & secrets. On the Client secrets tab, click New client secret.

Certificates and secrets page with New client secret button highlighted

Step 5: Add a description and expiry

In the Add a client secret panel, enter a description (for example, Frontegg Integration) and choose an expiry period. Click Add.

Add a client secret panel with description field filled in and Add button highlighted

Step 6: Copy the client secret value

The new secret appears in the list. Copy the Value immediately — it is only shown once. After you navigate away, you cannot retrieve it again.

Save your Client Secret now

The Client Secret value is only displayed once. After you leave this page, you can only see the secret ID — not the value. Store the value securely before continuing.

Client secret list showing the new secret with value blurred and highlighted

Configure API permissions

Step 7: Open API permissions

In the left sidebar, click API permissions, then click Add a permission.

API permissions page with Add a permission button highlighted

Step 8: Select Power BI Service

In the Request API permissions panel, scroll to Commonly used Microsoft APIs and click Power BI Service.

Request API permissions panel with Power BI Service highlighted

Step 9: Select delegated permissions

Click Delegated permissions. Expand each permission group and select the scopes your application requires. Select the following scopes:

ScopeDescription
App.Read.AllView all Power BI apps the user has access to
Dashboard.Read.AllRead dashboards
Dashboard.ReadWrite.AllRead and write dashboards
Dataflow.ReadWrite.AllRead and write dataflows (Premium or Premium Per User required)
Dataset.Read.AllView all datasets
Dataset.ReadWrite.AllRead and write all datasets (create, refresh, delete)
Report.Read.AllRead reports
Report.ReadWrite.AllRead and write reports (clone, delete, export)
Workspace.Read.AllView all workspaces
Workspace.ReadWrite.AllRead and write all workspaces and their members

Click Add permissions.

How Power BI scopes are issued

Frontegg requests Power BI access using the resource-scoped https://analysis.windows.net/powerbi/api/.default scope. Microsoft Entra ID returns the union of all delegated Power BI permissions you have pre-authorized on this app — only the scopes you select here will be included in the issued token.

Delegated permissions list with selected Power BI Service scopes

Step 10: Verify configured permissions

After adding permissions, the API permissions page lists all configured permissions under Power BI Service.

API permissions page showing all configured Power BI Service permissions

Configure the Frontegg portal

Once you have your Client ID, Client Secret, and Directory (tenant) ID, enter them in the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Power BI.
  2. Enter the Client ID and Client Secret in the corresponding fields.
  3. Optionally, enter the Directory (tenant) ID. Leave blank or set to common for multi-tenant applications; use a tenant GUID or domain for single-tenant applications.
  4. Click Save.

Keep your credentials secure

Never share or commit your Client Secret to version control.

Additional resources